<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cyber crime &#8211; EFA | European Fundraising Association</title>
	<atom:link href="https://efa-net.eu/tag/cyber-crime/feed/" rel="self" type="application/rss+xml" />
	<link>https://efa-net.eu</link>
	<description>One Voice, One Goal, Better Fundraising</description>
	<lastBuildDate>Mon, 14 Sep 2026 08:16:31 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.7</generator>

<image>
	<url>https://efa-net.eu/wp-content/uploads/2018/08/cropped-EFA-4colours-square-1-32x32.jpg</url>
	<title>cyber crime &#8211; EFA | European Fundraising Association</title>
	<link>https://efa-net.eu</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cyber attack on CRM used by 1,000-plus UK and Ireland charities</title>
		<link>https://efa-net.eu/news/cyber-attack-on-crm-used-by-1000-plus-uk-and-ireland-charities/</link>
		
		<dc:creator><![CDATA[Melanie May]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 10:33:25 +0000</pubDate>
				<category><![CDATA[Ireland]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[United Kingdom]]></category>
		<category><![CDATA[cyber crime]]></category>
		<guid isPermaLink="false">https://efa-net.eu/?p=15849</guid>

					<description><![CDATA[A cloud-based data platform used by more than 1,000 charities in the UK and Ireland fell victim to a cyber attack in July, compromising the personal<span class="excerpt-hellip"> […]</span>]]></description>
										<content:encoded><![CDATA[<p>A cloud-based data platform used by more than 1,000 charities in the UK and Ireland fell victim to a cyber attack in July, compromising the personal data of a significant number of donors.</p>
<p><a href="https://www.beaconcrm.org/" target="_blank" rel="noopener">Beacon</a> informed its customers of the attack on 4 August, which it said started in the early hours of the morning on 27 July. Beacon immediately reported the incident to the Information Commissioner’s Office and the authorities, bringing in expert support to help it conduct an investigation.</p>
<p>While the investigation confirmed that a copy of the database holding all Beacon customer data, including attachment files, was made and likely downloaded in a readable format by the threat actor, it found no evidence that any bank card details had been compromised, or that the data stolen had been “published, disclosed, or otherwise misused”.</p>
<p>The <a href="https://www.beaconcrm.org/incident-report" target="_blank" rel="noopener">most recent update</a> posted on its website (3 September) concluded the investigation, and said that while the threat actor had not been engaged with, they had contacted Beacon once towards the conclusion of the investigation to indicate they would be deleting any data they have exfiltrated and that no copy would be retained, sold, or shared. Beacon adds that dark web monitoring has found no mention of this incident or data related to it online, and that there is no evidence this was a targeted attack on Beacon, or any specific Beacon customer. Everything learned has been shared with law enforcement.</p>
<p>According to Beacon, the probable root cause of the incident was a compromised AWS access key. These are credentials used to allow the Beacon application to communicate securely with Amazon Web Services, its primary cloud hosting provider. Beacon’s understanding is that this access key was inadvertently exposed in its application code and subsequently used to gain unauthorised access to the organisation’s AWS environment.</p>
<p>The vulnerability that enabled this to happen has since been fixed, and measures implemented to ensure it cannot happen again. These are listed in Beacon’s report, accessible <a href="https://www.beaconcrm.org/incident-report" target="_blank" rel="noopener">here</a>.</p>
<p>During its investigation, Beacon published an <a href="https://www.beaconcrm.org/incident-faqs" target="_blank" rel="noopener">Incident FAQs</a> and <a href="https://www.beaconcrm.org/incident-guidance" target="_blank" rel="noopener">Incident Guidance</a> page on its website, providing advice and explanations of the situation and what customers should do next. These also clarified that Beacon was still “operating normally” and that charities could continue to collect payments through it. In a statement to <em>Fundraising Europe </em>on 1 September<em>, </em>Beacon said:</p>
<p><em>“Since containing the initial incident, we have not identified or observed any ongoing unauthorised access to Beacon’s systems. Our customers continue to access our platform and services as normal.&#8221;</em></p>
<p>Beacon’s website says it is used by more than 1,000 charities. The company is based in London and most client case studies on its website are charities based in the UK, with at least two from the Republic of Ireland.</p>
<p><strong>Reports to regulator &amp; maintaining supporter trust</strong></p>
<p>Following the incident, Beacon and the Charity Commission for England and Wales (CCEW) advised that charities should consider their reporting obligations, such as whether they needed to report the incident to the CCEW, to the Information Commissioner’s Office (ICO) or other regulators. CCEW&#8217;s <a href="https://www.gov.uk/government/news/guidance-for-charities-affected-by-the-beacon-cyber-security-incident" target="_blank" rel="noopener">statement</a> also said:</p>
<p><em>“We know many Beacon customers have moved promptly to inform their supporters about this incident. Clear communication with your charity’s stakeholders is crucial to retaining trust and protecting the relationships that sustain your work.”</em></p>
<p><em> </em>The <a href="https://www.fundraisingregulator.org.uk/news/advice-charities-affected-beacon-cyber-security-incident" target="_blank" rel="noopener">Fundraising Regulator also said</a> that all charities impacted needed to submit a report through its website.</p>
<p>The CCEW provides <a href="https://www.gov.uk/guidance/how-to-report-a-serious-incident-in-your-charity" target="_blank" rel="noopener">guidance on how to report a serious incident</a> and how to protect charities from <a href="https://www.gov.uk/guidance/protect-your-charity-from-cyber-crime" target="_blank" rel="noopener">cyber crime</a> and <a href="https://www.gov.uk/government/publications/internal-financial-controls-for-charities-cc8/protect-your-charity-from-fraud" target="_blank" rel="noopener">fraud</a>.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
